Debian Package Tracker
Register | Log in
Subscribe

poppler

Choose email to subscribe with

general
  • source: poppler (main)
  • version: 22.12.0-2
  • maintainer: Debian freedesktop.org maintainers (archive) (DMD)
  • uploaders: Pino Toscano [DMD] – Emilio Pozuelo Monfort [DMD] – Loic Minier [DMD]
  • arch: all any
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.71.0-5
  • o-o-sec: 0.71.0-5+deb10u2
  • oldstable: 20.09.0-3.1+deb11u1
  • old-sec: 20.09.0-3.1+deb11u1
  • stable: 22.12.0-2
  • testing: 22.12.0-2
  • unstable: 22.12.0-2
  • exp: 23.08.0-2
versioned links
  • 0.71.0-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.71.0-5+deb10u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20.09.0-3.1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 22.12.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 23.08.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gir1.2-poppler-0.18
  • libpoppler-cpp-dev
  • libpoppler-cpp0v5
  • libpoppler-dev
  • libpoppler-glib-dev
  • libpoppler-glib-doc
  • libpoppler-glib8
  • libpoppler-private-dev (1 bugs: 0, 0, 1, 0)
  • libpoppler-qt5-1
  • libpoppler-qt5-dev
  • libpoppler-qt6-3
  • libpoppler-qt6-dev
  • libpoppler126
  • poppler-utils (48 bugs: 0, 29, 19, 0)
action needed
A new upstream version is available: 23.10.0 high
A new upstream version 23.10.0 is available, you should consider packaging it.
Created: 2022-09-02 Last update: 2023-10-08 02:41
3 security issues in trixie high

There are 3 open security issues in trixie.

3 important issues:
  • CVE-2019-9543: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.
  • CVE-2019-9545: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.
  • CVE-2023-34872: A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
Created: 2023-06-11 Last update: 2023-08-27 23:31
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2019-9543: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.
  • CVE-2019-9545: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.
  • CVE-2023-34872: A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.
Created: 2022-07-04 Last update: 2023-08-27 23:31
10 security issues in buster high

There are 10 open security issues in buster.

2 important issues:
  • CVE-2020-18839: Buffer Overflow vulnerability in HtmlOutputDev::page in poppler 0.75.0 allows attackers to cause a denial of service.
  • CVE-2020-23804: Uncontrolled Recursion in pdfinfo, and pdftops in poppler 0.89.0 allows remote attackers to cause a denial of service via crafted input.
4 issues postponed or untriaged:
  • CVE-2022-37050: (needs triaging) In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.
  • CVE-2022-37051: (needs triaging) An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.
  • CVE-2022-37052: (needs triaging) A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
  • CVE-2022-38349: (needs triaging) An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.
4 ignored issues:
  • CVE-2019-9543: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.
  • CVE-2019-9545: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.
  • CVE-2019-10871: An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
  • CVE-2019-11026: FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.
Created: 2023-08-23 Last update: 2023-08-27 23:31
lintian reports 3 errors and 4 warnings high
Lintian reports 3 errors and 4 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2023-01-11 Last update: 2023-02-03 15:05
8 bugs tagged patch in the BTS normal
The BTS contains patches fixing 8 bugs (9 if counting merged bugs), consider including or untagging them.
Created: 2023-09-13 Last update: 2023-10-08 02:33
8 low-priority security issues in bullseye low

There are 8 open security issues in bullseye.

6 issues left for the package maintainer to handle:
  • CVE-2020-36023: (needs triaging) An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.
  • CVE-2020-36024: (needs triaging) An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.
  • CVE-2022-37050: (needs triaging) In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.
  • CVE-2022-37051: (needs triaging) An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.
  • CVE-2022-37052: (needs triaging) A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
  • CVE-2022-38349: (needs triaging) An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.

You can find information about how to handle these issues in the security team's documentation.

2 ignored issues:
  • CVE-2019-9543: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.
  • CVE-2019-9545: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.
Created: 2022-07-04 Last update: 2023-08-27 23:31
3 low-priority security issues in bookworm low

There are 3 open security issues in bookworm.

1 issue left for the package maintainer to handle:
  • CVE-2023-34872: (needs triaging) A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open.

You can find information about how to handle this issue in the security team's documentation.

2 ignored issues:
  • CVE-2019-9543: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readGenericBitmap() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfseparate binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JArithmeticDecoder::decodeBit.
  • CVE-2019-9545: An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.
Created: 2023-06-10 Last update: 2023-08-27 23:31
Build log checks report 3 warnings low
Build log checks report 3 warnings
Created: 2017-10-26 Last update: 2023-01-13 03:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.2 instead of 4.6.1).
Created: 2022-05-11 Last update: 2023-01-11 08:25
testing migrations
  • This package will soon be part of the auto-poppler transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2023-08-16] Accepted poppler 23.08.0-2 (source) into experimental (Amin Bandali) (signed by: Jeremy Bicha)
  • [2023-08-14] Accepted poppler 0.71.0-5+deb10u2 (source) into oldoldstable (Adrian Bunk)
  • [2023-08-12] Accepted poppler 23.08.0-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Jeremy Bicha)
  • [2023-01-16] poppler 22.12.0-2 MIGRATED to testing (Debian testing watch)
  • [2023-01-10] Accepted poppler 22.12.0-2 (source) into unstable (Jeremy Bicha)
  • [2022-12-15] Accepted poppler 22.12.0-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Jeremy Bicha)
  • [2022-11-01] Accepted poppler 22.11.0-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Jeremy Bicha)
  • [2022-09-25] Accepted poppler 0.71.0-5+deb10u1 (source) into oldstable (Markus Koschany)
  • [2022-09-11] Accepted poppler 20.09.0-3.1+deb11u1 (source) into proposed-updates->stable-new, proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2022-09-11] poppler 22.08.0-2.1 MIGRATED to testing (Debian testing watch)
  • [2022-09-08] Accepted poppler 22.08.0-2.1 (source) into unstable (Salvatore Bonaccorso) (signed by: Jeremy Bicha)
  • [2022-09-06] Accepted poppler 20.09.0-3.1+deb11u1 (source) into stable-security->embargoed, stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2022-08-24] poppler 22.08.0-2 MIGRATED to testing (Debian testing watch)
  • [2022-08-21] Accepted poppler 22.08.0-2 (source) into unstable (Jeremy Bicha)
  • [2022-08-10] Accepted poppler 22.08.0-1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Jeremy Bicha)
  • [2022-06-14] Accepted poppler 22.06.0-1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Sebastien Bacher)
  • [2022-03-20] poppler 22.02.0-3 MIGRATED to testing (Debian testing watch)
  • [2022-03-17] Accepted poppler 22.02.0-3 (source) into unstable (Jeremy Bicha)
  • [2022-02-07] Accepted poppler 22.02.0-2 (source) into experimental (Jeremy Bicha)
  • [2022-02-05] Accepted poppler 22.02.0-1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Jeremy Bicha)
  • [2021-11-06] Accepted poppler 21.11.0-1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Sebastien Bacher)
  • [2021-06-21] Accepted poppler 21.06.1-1 (source) into experimental (Sebastien Bacher)
  • [2021-06-11] Accepted poppler 21.06.0-1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Sebastien Bacher)
  • [2021-02-27] Accepted poppler 21.02.0-1 (source amd64 all) into experimental, experimental (Debian FTP Masters) (signed by: Sebastien Bacher)
  • [2021-01-24] poppler 20.09.0-3.1 MIGRATED to testing (Debian testing watch)
  • [2021-01-21] Accepted poppler 20.09.0-3.1 (source) into unstable (Sebastien Bacher)
  • [2020-11-08] Accepted poppler 0.48.0-2+deb9u4 (source) into oldstable (Markus Koschany)
  • [2020-11-07] poppler 20.09.0-3 MIGRATED to testing (Debian testing watch)
  • [2020-11-03] Accepted poppler 20.09.0-3 (source) into unstable (Emilio Pozuelo Monfort)
  • [2020-09-07] poppler 20.09.0-2 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 104 110
  • RC: 0
  • I&N: 73 78
  • M&W: 31 32
  • F&P: 0
  • patch: 8 9
links
  • homepage
  • lintian (3, 4)
  • buildd: logs, exp, checks, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 23.08.0-2ubuntu1
  • 99 bugs (5 patches)
  • patches for 23.08.0-2ubuntu1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing